Skip to content

Commit

Permalink
Fix parsing of decimal numbers in non-English locales (#1273)
Browse files Browse the repository at this point in the history
  • Loading branch information
nscuro authored May 24, 2024
1 parent 04688c2 commit 92bd9de
Show file tree
Hide file tree
Showing 4 changed files with 11 additions and 7 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -64,6 +64,7 @@
import java.util.Collections;
import java.util.HashMap;
import java.util.List;
import java.util.Locale;
import java.util.Map;
import java.util.Objects;
import java.util.Optional;
Expand Down Expand Up @@ -305,7 +306,7 @@ private static List<VulnerabilityRating> parseCveImpact(Metrics metrics) {
CvssV2Data cvss = baseMetric.getCvssData();
Optional.ofNullable(cvss)
.map(cvss20 -> VulnerabilityRating.newBuilder()
.setScore(Double.parseDouble(NumberFormat.getInstance().format(cvss20.getBaseScore())))
.setScore(Double.parseDouble(NumberFormat.getInstance(Locale.US).format(cvss20.getBaseScore())))
.setMethod(ScoreMethod.SCORE_METHOD_CVSSV2)
.setVector(cvss20.getVectorString())
.setSeverity(mapSeverity(baseMetric.getBaseSeverity()))
Expand All @@ -322,7 +323,7 @@ private static List<VulnerabilityRating> parseCveImpact(Metrics metrics) {
CvssV3Data cvss = baseMetric.getCvssData();
Optional.ofNullable(cvss)
.map(cvssx -> VulnerabilityRating.newBuilder()
.setScore(Double.parseDouble(NumberFormat.getInstance().format(cvssx.getBaseScore())))
.setScore(Double.parseDouble(NumberFormat.getInstance(Locale.US).format(cvssx.getBaseScore())))
.setMethod(ScoreMethod.SCORE_METHOD_CVSSV3)
.setVector(cvssx.getVectorString())
.setSeverity(mapSeverity(cvssx.getBaseSeverity().value()))
Expand All @@ -339,7 +340,7 @@ private static List<VulnerabilityRating> parseCveImpact(Metrics metrics) {
CvssV3Data cvss = baseMetric.getCvssData();
Optional.ofNullable(cvss)
.map(cvss31 -> VulnerabilityRating.newBuilder()
.setScore(Double.parseDouble(NumberFormat.getInstance().format(cvss.getBaseScore())))
.setScore(Double.parseDouble(NumberFormat.getInstance(Locale.US).format(cvss.getBaseScore())))
.setMethod(ScoreMethod.SCORE_METHOD_CVSSV31)
.setVector(cvss.getVectorString())
.setSeverity(mapSeverity(cvss.getBaseSeverity().value()))
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -50,6 +50,7 @@
import java.util.ArrayList;
import java.util.Collections;
import java.util.List;
import java.util.Locale;
import java.util.Map;
import java.util.Objects;
import java.util.Optional;
Expand Down Expand Up @@ -270,7 +271,7 @@ private static List<VulnerabilityRating> parseCvssRatings(JSONObject object, Sev
var rating = VulnerabilityRating.newBuilder();
double score = cvss.calculateScore().getBaseScore();
rating.setVector(vector);
rating.setScore(Double.parseDouble(NumberFormat.getInstance().format(score)));
rating.setScore(Double.parseDouble(NumberFormat.getInstance(Locale.US).format(score)));
String type = cvssObj.optString("type", null);

if (type != null && type.equalsIgnoreCase("CVSS_V3")) {
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -35,6 +35,7 @@

import java.text.NumberFormat;
import java.util.List;
import java.util.Locale;
import java.util.Optional;

import static org.cyclonedx.proto.v1_4.ScoreMethod.SCORE_METHOD_CVSSV2;
Expand Down Expand Up @@ -116,15 +117,15 @@ private static VulnerabilityRating convertRating(final String cvssVector) {
return VulnerabilityRating.newBuilder()
.setSource(Source.newBuilder().setName("OSSINDEX"))
.setMethod(SCORE_METHOD_CVSSV3)
.setScore(Double.parseDouble(NumberFormat.getInstance().format(score.getBaseScore())))
.setScore(Double.parseDouble(NumberFormat.getInstance(Locale.US).format(score.getBaseScore())))
.setVector(cvss.getVector())
.setSeverity(convert(normalizedCvssV3Score(score.getBaseScore())))
.build();
} else if (cvss instanceof CvssV2) {
return VulnerabilityRating.newBuilder()
.setSource(Source.newBuilder().setName("OSSINDEX"))
.setMethod(SCORE_METHOD_CVSSV2)
.setScore(Double.parseDouble(NumberFormat.getInstance().format(score.getBaseScore())))
.setScore(Double.parseDouble(NumberFormat.getInstance(Locale.US).format(score.getBaseScore())))
.setVector(cvss.getVector())
.setSeverity(convert(normalizedCvssV2Score(score.getBaseScore())))
.build();
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -42,6 +42,7 @@
import java.util.Comparator;
import java.util.HashSet;
import java.util.List;
import java.util.Locale;
import java.util.Objects;
import java.util.Optional;
import java.util.function.Predicate;
Expand Down Expand Up @@ -215,7 +216,7 @@ private static VulnerabilityRating convert(final Severity severity) {
default -> SEVERITY_UNKNOWN;
})
.setMethod(determineScoreMethod(severity))
.setScore(Double.parseDouble(NumberFormat.getInstance().format(severity.score())))
.setScore(Double.parseDouble(NumberFormat.getInstance(Locale.US).format(severity.score())))
.setVector(severity.vector())
.build();
}
Expand Down

0 comments on commit 92bd9de

Please sign in to comment.